urlology.blob.core.windows.net

Microsoft Corporation

Domain Information

The domain urlology.blob.core.windows.net registered by Microsoft Corporation was initially registered in August of 1995 through MARKMONITOR INC.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Redmond, Washington within the United States which resides on the Microsoft Corporation network.
Registrar:
MARKMONITOR INC.

Server location:
Washington, United States (US)

Create date:
Thursday, August 10, 1995

Expires date:
Saturday, June 4, 2016

Updated date:
Wednesday, October 8, 2014

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.Installer.Meta, PUP.Installer.TrafficSpace, PUP.Installer.HudsonExchangeGroup, PUP.HudsonExchangeGroup.Installer, PUP.HudsonExchangeGroup.Installer (M), PUP.TrafficSpace.Installer (M)
100.00%

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF, NS:PUF.SilenceInstaller!1.9DDF[F1]
87.80%

Dr.Web
Adware.Downware.9973, Adware.Downware.10482, Adware.Downware.10994, Adware.Downware.11268
60.98%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen, HEUR/QVM40.1.Malware.Gen, HEUR/QVM21.1.Malware.Gen, HEUR/QVM42.1.Malware.Gen
53.66%

AVG
AdPlugin, Generic
39.02%

Trend Micro House Call
Suspici.326C0565, Suspicious_GEN.F47V0326, Suspicious_GEN.F47V0403, Suspicious_GEN.F47V0413, Suspicious_GEN.F47V0505, Suspici.AFE8286D
31.71%

VIPRE Antivirus
InstallerTech
26.83%

Bkav FE
W32.HfsAdware
24.39%

McAfee
Artemis!04478039C8E1, Artemis!CAE63A6DC1CC, Artemis!1F762BB62B62, Artemis!1CC5A993A3D0, Artemis!0289298DA719
14.63%

Sophos
Mal/Generic-S, Open Software Updater (PUA)
12.20%

herdProtect (fuzzy)
a variant of 628f079e676c8ab5d26d1e4aeaa85c561736dbd6, a variant of 1369ac3e359d46cf42408c810851acaa76ab55bf, a variant of b1762d07bfe05b5a1ac857145300f109e5df658d
9.76%

avast!
Win32:Malware-gen, Win32:Evo-gen [Susp]
7.32%

ESET NOD32
Win32/Packed.VMDetector.Q potentially unwanted, Win32/DownWare.AJ potentially unwanted, Win32/Adware.OpenSUpdater
7.32%

Panda Antivirus
Generic Suspicious
7.32%

Avira AntiVirus
TR/Spy.Gen
4.88%

The domain urlology.blob.core.windows.net has been seen to resolve to the following IP address.

blob.bn4prdstr01a.store.core.windows.net
May 5, 2015

File downloads found at URLs served by urlology.blob.core.windows.net.

6 / 68      (PUP)

3 / 68      (PUP)
http://urlology.blob.core.windows.net/.../SetupNow.exe  (5b5036f76f7e441e99c2705aff7f40a0)

9 / 68      (PUP)
https://urlology.blob.core.windows.net/.../SetupNow.exe  (55a8e154e120c0d7acc1da943fff2710)

1 / 68      (Adware)

1 / 68      (Adware)

6 / 68      (PUP)
http://urlology.blob.core.windows.net/.../SetupNew.exe  (70d7c198c456d8ef59e1c7eb58fe667a)

2 / 68      (PUP)

1 / 68      (Adware)
http://urlology.blob.core.windows.net/.../StartSetup.exe  (e1cb6deb560eaf4c0eeeb8e64061a360)

6 / 68      (Adware)

11 / 68    (Adware)
http://urlology.blob.core.windows.net/.../Setup_OSU.exe  (0289298da719e873a2d59b73f1b6750d)

7 / 68      (PUP)
http://urlology.blob.core.windows.net/.../SetupStart.exe  (607a15ccce8016254c23607e929f4c8f)

1 / 68      (Adware)

9 / 68      (PUP)

2 / 68      (PUP)
https://urlology.blob.core.windows.net/.../Setup.exe  (367b68d657ff3b91b895da3bdc0e6f6e)

URL:
http://urlology.blob.core.windows.net/

SSL certificate subject:
CN=*.blob.core.windows.net

SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Web server:
Microsoft-HTTPAPI/2.0